SECOMPSSECOMPS
Home/Services/Mobile
SVC 04

Mobile application penetration testing.

App store approval is a policy review, not a security review. We test iOS and Android builds statically and at runtime, and we test the API behind them, because that is where the data actually lives.

At a glance

Typical duration
1 to 2 weeks per platform
Platforms
iOS and Android
Standards
OWASP MASVS and MASTG
Includes
Backend API testing as standard
Retest
Included
01Overview

What we look for.

A mobile binary is shipped to the attacker. Anything embedded in it, from API keys to business logic to certificate pinning, is available to anyone patient enough to unpack it. We test on the assumption that the client is fully controlled by an adversary, because it is.

02Coverage

What we test.

Insecure data storageCredentials, tokens and personal data in preferences, databases, caches, logs and backups.
Transport securityCertificate validation and pinning, pinning bypass under a hooked runtime, cleartext fallbacks.
Authentication and session handlingToken lifetime and storage, biometric bypass, device binding, logout and revocation behaviour.
Reverse engineering resistanceHardcoded secrets and endpoints, obfuscation effectiveness, debug and test code shipped to production.
Runtime manipulationHooking and instrumentation, root and jailbreak detection bypass, tamper detection effectiveness.
Platform interactionDeep links and URL schemes, exported components and intents, clipboard and screenshot exposure, keyboard caching.
Backend APIThe full API test surface, because a hardened client in front of a permissive API protects nothing.
Third-party SDKsWhat analytics, advertising and crash-reporting libraries collect and transmit.
03Deliverables

What you receive.

01Executive summary

Risk posture in plain language for leadership and the board, with the two or three things that actually matter.

02Technical findings

Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.

03Compliance annex

Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.

04Attestation letter

A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.

04Fit

Who needs this.

  • Consumer fintech and banking applications
  • Healthcare applications handling patient data
  • Any application storing authentication tokens on device
  • Products entering enterprise mobile device management review
  • Teams shipping to app stores without an independent security review
05Questions

Frequently asked.

Do you need the source code?

No, we can test the compiled build. Source access makes the review deeper and faster, and pairs well with a secure code review, but it is not required.

Do you test on real devices or emulators?

Both. Emulators are efficient for instrumentation and rapid iteration, and real devices are necessary to validate biometric flows, hardware-backed key storage and platform behaviour that emulators approximate.

Is the backend API included?

Yes. Testing a mobile client without its API produces a report that misses where the real risk sits. If the API is large or shared across products, we may recommend a dedicated API engagement alongside.

What about React Native or Flutter builds?

Both are supported. Cross-platform frameworks change how we unpack and instrument the build, not what we test for, and they frequently make bundled logic and secrets easier to recover.

Ready to find out what an attacker would find?

Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.